Skip to content

AIR

AIR builds a runtime context firewall that vets and monitors the skills, plugins, and MCP tools enterprise AI agents connect to.

Visit Website ↗ + Add to Compare Claim This Company
57/100Incremental Innovator

Overview

AIR (air.security) is a Tel Aviv-based startup founded in February 2026 by Yair Saban (CEO) and Niv Hoffman (CTO), both veterans of Israel’s Unit 8200 signals-intelligence unit. The company emerged from stealth on September 1, 2026 with $50 million raised across two seed rounds ($10M led by Sequoia Capital, followed by $40M led by Greenoaks), with participation from individual investors including Wiz co-founder Yinon Costica. Former Disney and Costco CISO Ryan Knisley joined as Chief Strategy Officer. At the time of its funding announcement the company reported roughly 40 employees and more than 20 paying customers, about a quarter of them large enterprises, concentrated in financial services and pharma.

The product, marketed as a ‘context firewall for AI agents,’ sits between enterprise AI agents and the external skills, plugins, and Model Context Protocol (MCP) servers those agents try to use. It has four components: Control (discovery and policy governance of agent fleets), Filter (pre-deployment vetting of add-ons for malicious instructions, excessive permissions, or supply-chain risk), Defend (runtime monitoring and blocking), and a curated Marketplace of pre-vetted add-ons. AIR’s own research, cited in press coverage, claims to have found over 17,800 public AI add-ons with 6.7 million installs relying on untrusted instruction sources, plus fake ‘skills’ impersonating Anthropic and OpenAI to slip past review.

The company’s differentiator is narrow focus: rather than general LLM security or prompt-injection filtering, it specifically targets the software-supply-chain risk created by autonomous agents installing third-party skills and MCP tools without human review. This is a genuine and fast-growing problem as agentic AI adoption accelerates, but AIR competes with several other very recently funded ‘AI agent security’ and ‘MCP security’ entrants, and as a six-month-old company it has no long-run track record.

Innovation Matrix Assessment

Innovation Velocity 6/10

Shipped four distinct product modules and published original threat research within six months of founding, but it is too early to show a repeatable cadence of advances.

Operational Value 7/10

Addresses a concrete, growing operational gap — enterprises deploying AI agents with little visibility into what plugins or MCP tools those agents install and use.

Market Momentum 7/10

$50M raised from top-tier investors (Sequoia, Greenoaks) and 20+ named customers within six months is unusually strong momentum for a company this young, per independent TechCrunch, SecurityWeek, and Calcalist reporting.

Category Disruption 5/10

AI agent and MCP security is a real emerging category, but AIR is one of several well-funded entrants racing into it simultaneously, not a clear category creator.

Real-World Efficacy 3/10

No independent third-party testing, named customer incident, or analyst validation was found; the threat-research statistics cited in press coverage originate from AIR itself.

Enduring Relevance 6/10

Agentic AI supply-chain risk is likely to remain a live problem for years, but the vendor landscape is crowded and could consolidate quickly.

Why CISOs Should Care

As agents begin auto-installing third-party skills and MCP integrations, CISOs need a control point to vet and monitor those add-ons before they touch internal systems or data.

What Makes It Different

Rather than filtering LLM prompts or outputs generally, AIR focuses specifically on vetting and governing the software supply chain of agent add-ons (skills, plugins, MCP servers) before and during runtime.

The Matrix Verdict

57/100 — INCREMENTAL INNOVATOR

AIR shows genuine product breadth and unusually strong early funding and customer traction for a six-month-old company, but has no independently verified efficacy evidence yet and competes in a fast-forming, crowded niche.

Editorial Note: Claims vs. Verified Findings

Funding amount, investors, founder backgrounds, and customer count are corroborated by independent outlets (TechCrunch, SecurityWeek, Calcalist). The specific threat-research statistics (17,800 add-ons, 6.7M installs) are AIR's own self-published research and have not been independently replicated.

Sources